StorageCrypt ransomware, a coinminer and more
ID: bb1e73c4-c3f2-554a-841c-8ca55f6cdeb3
STIX ID: report--bb1e73c4-c3f2-554a-841c-8ca55f6cdeb3
Feed Name: Blaze's Security Blog
Analysis of a campaign associated with “StorageCrypt” shows a Windows component (“美女与野兽.exe”) exhibiting worm/backdoor behavior and a Linux intrusion chain exploiting SambaCry (CVE-2017-7494) to download additional payloads, chiefly a Monero miner with a watchdog, from C2 45.76.102.45; indicators include multiple filenames and hashes, pool config (xmr.pool.minergate.com:45560), and the user email [email protected]. While ransomware is referenced, the observed artifacts primarily perform coin-mining and backdoor activities; immediate patching of Samba is advised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
